Jon Chery
|
ea42a17474
|
feat(P4): linux node join remote ingress bootstrap (REQ-174)
Add ingress.BootstrapRemoteIngress: renders+writes traefik static
config, renders+writes+applies nft DNAT/SNAT, pushes step-ca root CA,
ensures podman traefik container — all over SSH exec. Uses a heredoc-
based remoteWriteFile with a random delimiter (F9 injection guard).
Wired into linux/bootstrap.go Step 4d, replacing the standalone
EnsureTraefikContainerRemote call with the full ingress stack.
C-60: uses certpaths.CACertPath() (not CAPath).
C-58: mounts host-side traefik.yml (preserves REQ-100 opt-out).
C-55: pre-creates nft table before nft -f.
---ci---
project: orca
phase: 4
milestone: v0.14
status: execute
---/ci---
|
2026-08-10 20:11:32 +00:00 |
|
Jon Chery
|
5013209e31
|
feat(P3): nft SNAT+DNAT + orca init ingress bootstrap (REQ-173)
nft emitter (internal/emitter/nft.go):
- Add DNATTarget field (C-51: validated via net.ParseIP; injection
guard). Default 127.0.0.1; proxmox native uses LXC bridge IP.
- Add EnableSNAT field (default true for zero-value config).
- Add postrouting masquerade chain (research Topic 1):
ip saddr 127.0.0.0/8 oifname != lo masquerade
- Shift input/forward priority from filter (=0) to -10 (research
Topic 2: pve-firewall coexistence — avoids same-priority undefined
evaluation order).
internal/ingress/bootstrap.go (new):
- BootstrapLocalIngress: mkdir dirs, push step-ca root CA (C-60:
certpaths.CACertPath not CAPath), render+write traefik static
config (C-58: preserves traefik-on-public-ip opt-out), render+
write+apply nft ruleset, pre-create table (C-55: avoids first-
apply flush-table error), ensure podman container. All non-fatal.
init.go: Step 4d now calls ingress.BootstrapLocalIngress (R-024).
doctor_nft.go: assert postrouting masquerade + priority -10.
Tests: nft_test.go — DNATTarget substitution, invalid DNATTarget
rejection (C-51), EnableSNAT=false omits postrouting, priority -10.
---ci---
project: orca
phase: 3
milestone: v0.14
status: execute
---/ci---
|
2026-08-10 20:09:26 +00:00 |
|